US10708163B1ActiveUtility

Methods, systems, and computer readable media for automatic configuration and control of remote inline network monitoring probe

Assignee: KEYSIGHT TECHNOLOGIES INCPriority: Jul 13, 2018Filed: Jul 13, 2018Granted: Jul 7, 2020
Est. expiryJul 13, 2038(~12 yrs left)· nominal 20-yr term from priority
Inventors:Jonathan Stroud
H04L 2101/622H04L 61/5007H04L 43/12H04L 43/0888H04L 43/087H04L 43/0852H04L 43/026H04L 41/0886H04L 63/0227H04L 69/22H04L 61/6022
78
PatentIndex Score
3
Cited by
59
References
14
Claims

Abstract

A method for automatic configuration and control of a remote inline network monitoring probe includes receiving packets from a router or firewall associated with a network being monitored by the inline network monitoring probe. A source medium access control (MAC) and a source IP address are extracted from a first packet of the packets received from the router or firewall. The method further includes storing the source IP address and the source MAC address in memory of the inline network monitoring probe. The method further includes changing a MAC address of the inline network monitoring probe to the source MAC address. The method includes assigning the source IP address to the inline network monitoring probe. The method further includes using the source MAC address and the source IP address to communicate with a remote network monitoring control center.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
       1. A method for automatic configuration and control of a remote inline network monitoring probe, the method comprising:
 at an inline network monitoring probe including a central processing unit (CPU):
 receiving packets from a router or firewall associated with a network being monitored by the inline network monitoring probe; 
 extracting, from a first packet of the packets received from the router or firewall, a source medium access control (MAC) address and a source Internet protocol (IP) address; 
 storing the source IP address and the source MAC address in memory of the inline network monitoring probe; 
 changing a MAC address of the inline network monitoring probe to the source MAC address; 
 assigning the source IP address to the inline network monitoring probe; and 
 using the source MAC address and the source IP address to communicate with a remote network monitoring control center 
 wherein the inline network monitoring probe includes a first port for connecting to a router or firewall and a second port for connecting to a modem or access point, wherein the inline network monitoring probe is configured to recognize at least one trusted IP address as being associated with the remote monitoring control center, and wherein using the source IP address and the source MAC address to communicate with the remote monitoring control center includes:
 receiving a second packet over the second port; 
 identifying a destination MAC address in the second packet as being the source MAC address extracted from the first packet; 
 identifying a destination IP address in the second packet as being the source IP address extracted from the first packet, and, in response, examining a source IP address in the second packet; and 
 determining that the source IP address in the second packet is the at least one trusted IP address, and, in response, identifying the second packet as being a control packet from the remote monitoring control center. 
 
 
 
     
     
       2. The method of  claim 1  wherein receiving packets from the router or firewall associated with the network being monitored includes receiving IP packets and wherein the source IP address in the first packet is a public IP address of the router or firewall. 
     
     
       3. The method of  claim 1  comprising, in response to identifying the second packet as being associated with the remote monitoring control center, responding to the second packet. 
     
     
       4. The method of  claim 1  wherein the destination IP address in the second packet comprises a spoofed IP address of the router or firewall. 
     
     
       5. The method of  claim 1  wherein the inline network monitoring probe passively monitors packets transmitted to the protected network, generates statistics regarding the monitored packets, and communicates the statistics to the remote monitoring control center. 
     
     
       6. The method of  claim 5  wherein the statistics comprise remote monitoring (RMON) statistics. 
     
     
       7. A system for automatic configuration and control of a remote inline network monitoring probe, the system comprising:
 an inline network monitoring probe including:
 a central processing unit (CPU); 
 a first network port for receiving packets from a router or firewall associated with a network being monitored by the inline network monitoring probe; 
 a second port for connecting to a modem or access point; and 
 an auto-configuration module for extracting, from a first packet of the packets received from the router or firewall, a source medium access control (MAC) address and a source Internet protocol (IP) address, storing the source IP address and the source MAC address in memory of the inline network monitoring probe, changing a MAC address of the inline network monitoring probe to the source MAC address, and assigning the source IP address to the inline network monitoring probe, 
 wherein the inline network monitoring probe uses the source MAC address and the source IP address to communicate with a remote network monitoring control center, 
 wherein the inline network monitoring probe is configured to recognize at least one trusted IP address as being associated with the remote monitoring control center, and 
 wherein the inline network monitoring probe uses the source IP address and the source MAC address to communicate with the remote monitoring control center by:
 receiving a second packet over the second port; 
 identifying a destination MAC address in the second packet as being the source MAC address extracted from the first packet; 
 identifying a destination IP address in the second packet as being the source IP address extracted from the first packet, and, in response, examining a source IP address in the second packet; and 
 determining that the source IP address in the second packet is the at least one trusted IP address, and, in response, identifying the second packet as being a control packet from the remote monitoring control center. 
 
 
 
     
     
       8. The system of  claim 7  wherein the source IP address in the first packet is a public IP address of the router or firewall. 
     
     
       9. The system of  claim 7  wherein the inline probe is configured to, in response to identifying the second packet as being associated with the remote monitoring control center, respond to the second packet. 
     
     
       10. The system of  claim 9  wherein the destination IP address in the second packet comprises a spoofed IP address of the router or firewall. 
     
     
       11. The system of  claim 7  wherein the inline network monitoring probe is configured to forward traffic received over the second port that is not from the at least one trusted IP address to the router or firewall. 
     
     
       12. The system of  claim 7  wherein the inline network monitoring probe includes a monitoring module for monitoring packets transmitted to the protected network, generating statistics regarding the monitored packets, and communicates the statistics to the remote monitoring control center. 
     
     
       13. The system of  claim 12  wherein the statistics comprise remote monitoring (RMON) statistics. 
     
     
       14. A non-transitory computer readable medium having stored thereon executable instructions that when executed by a processor of a computer control the computer to perform steps comprising:
 at an inline network monitoring probe:
 receiving packets from a router or firewall associated with a network being monitored by the inline network monitoring probe; 
 extracting, from a first packet received from the router or firewall, a source medium access control (MAC) address and a source Internet protocol (IP) address; 
 storing the source IP address and the source MAC address in memory of the inline network monitoring probe; 
 changing a MAC address of the inline network monitoring probe to the source MAC address; 
 assigning the source IP address to the inline network monitoring probe; and
 using the source MAC address and the source IP address to communicate with a remote network monitoring control center, 
 
 wherein the inline network monitoring probe includes a first port for connecting to a router or firewall and a second port for connecting to a modem or access point, wherein the inline network monitoring probe is configured to recognize at least one trusted IP address as being associated with the remote monitoring control center wherein using the source IP address and the source MAC address to communicate with the remote monitoring control center includes:
 receiving a second packet over the second port; 
 identifying a destination MAC address in the second packet as being the source MAC address extracted from the first packet; 
 identifying a destination IP address in the second packet as being the source IP address extracted from the first packet, and, in response, examining a source IP address in the second packet; and 
 determining that the source IP address in the second packet is the at least one trusted IP address, and, in response, identifying the second packet as being a control packet from the remote monitoring control center.

Join the waitlist — get patent alerts

Track US10708163B1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.